Systems and methods for handling embedded controller diagnostic tests using a hardware-based security architecture driver of a heterogenous computing platform
A hardware-based security architecture driver for EC diagnostics on heterogenous platforms addresses inefficiencies by allowing concurrent operations without SMIs, improving system responsiveness and reducing boot times.
Patent Information
- Application Number
- US18/672152
- Authority / Receiving Office
- US · United States
- Patent Type
- Applications(United States)
- Current Assignee / Owner
- Filing Date
- 2024-05-23
- Publication Date
- 2025-11-27
AI Technical Summary
Existing systems face inefficiencies in handling Embedded Controller (EC) diagnostic tests on heterogenous computing platforms, leading to long boot sequences, idle host processor times, and tedious troubleshooting due to the need for System Management Interrupts (SMIs) during diagnostic operations.
Implementing a hardware-based security architecture driver that enables EC diagnostics without invoking System Management Interrupts (SMIs), allowing concurrent and prioritized diagnostic operations through a TRUSTZONE architecture, using buses like I2C, I3C, or eSPI, and applying policies based on context information.
Facilitates efficient multitasking and reduced boot times by enabling simultaneous EC diagnostic operations, enhancing system responsiveness and reducing host processor idle times.
Smart Images

Figure US20250363218A1-D00000_ABST
Abstract
Description
FIELD
[0001] This disclosure relates generally to Information Handling Systems (IHSs), and more specifically, to systems and methods for handling Embedded Controller (EC) diagnostic tests using a hardware-based security architecture driver of a heterogenous computing platform.BACKGROUND
[0002] As the value and use of information continues to increase, individuals and businesses seek additional ways to process and store it. One option available to users is an Information Handling System (IHS). An IHS generally processes, compiles, stores, and / or communicates information or data for business, personal, or other purposes thereby allowing users to take advantage of the value of the information. Because technology and information handling needs and requirements vary between different users or applications, IHSs may also vary regarding what information is handled, how the information is handled, how much information is processed, stored, or communicated, and how quickly and efficiently the information may be processed, stored, or communicated.
[0003] Variations in IHSs allow for IHSs to be general or configured for a specific user or specific use, such as financial transaction processing, airline reservations, enterprise data storage, or global communications. In addition, IHSs may include a variety of hardware and software components that may be configured to process, store, and communicate information and may include one or more computer systems, data storage systems, and networking systems.SUMMARY
[0004] Systems and methods for handling Embedded Controller (EC) diagnostic tests using a hardware-based security architecture driver of a heterogenous computing platform are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a heterogenous computing platform and an EC integrated into or coupled to the heterogenous computing platform, the EC configured to: receive, from a hardware-based security architecture driver of the heterogenous computing platform, a command to perform or trigger a diagnostic operation; and respond to the command.
[0005] The heterogenous computing platform may include: a System-On-Chip (SoC), a Field-Programmable Gate Array (FPGA), or an Application-Specific Integrated Circuit (ASIC). Additionally, or alternatively, the heterogenous computing platform may include a Reduced Instruction Set Computer (RISC) processor coupled to an interconnect. Moreover, the interconnect may include at least one of: an Advanced Microcontroller Bus Architecture (AMBA) bus, a QuickPath Interconnect (QPI) bus, or a HyperTransport (HT) bus.
[0006] In some cases, the hardware-based security architecture may include a TRUSTZONE architecture.
[0007] The request may be received by the EC from the heterogenous computing platform over an Inter-Integrated Circuit (I2C), Improved I2C (I3C), Serial Peripheral Interface (SPI), or Enhanced SPI (eSPI) bus. The command may be issued by a Basic Input / Output System (BIOS) of the heterogenous computing platform during a Driver Execution Environment (DXE) phase of a boot sequence.
[0008] The EC may be configured to perform or trigger the diagnostic operation in the absence of any System Management Interrupt (SMI) by the heterogenous computing platform. Additionally, or alternatively, the EC may be configured to perform or trigger the diagnostic operation concurrently with one or more diagnostic operations performed by the heterogenous computing platform. Additionally, or alternatively, to perform or trigger the diagnostic operation, the EC may be configured to communicate with at least one of: a fan, a cable, a battery, a temperature sensor, or a display identified based, at least in part, upon the request.
[0009] The EC may be configured to: receive, from the hardware-based security architecture driver, another command to perform or trigger another diagnostic operation; queue the other diagnostic operation; and respond to the other command. The command and the other command may be received in a same request issued by a Basic Input / Output System (BIOS) of the heterogenous computing platform to the hardware-based security architecture driver.
[0010] The EC may be configured to perform or trigger one or more diagnostic operations in the queue based, at least in part, upon a policy. The policy may include one or more rules usable by the EC to determine an order in which to perform or trigger the one or more diagnostic operations based, at least in part, upon context information.
[0011] The context information may include at least one of: a location of the IHS, an identity of a user of the IHS, a host Operating System (OS) of the IHS, or a network connectivity of the IHS.
[0012] In another illustrative, non-limiting embodiment, an IHS may include a heterogenous computing platform having a host processor and an EC coupled to the host processor, a method may include: receiving, by the EC from a hardware-based security architecture driver of the heterogenous computing platform, a command to trigger a diagnostic operation, where the command is issued by a BIOS; and handling the command. The method may include not triggering the diagnostic operation based, at least in part, upon a policy. Additionally, or alternatively, the method may include triggering another diagnostic operation based, at least in part, upon a policy.
[0013] In yet another illustrative, non-limiting embodiment, a heterogenous computing platform may include: a host processor configured to execute a BIOS and an EC coupled to the host processor, where the BIOS is configured to: transmit to the EC, through a hardware-based security architecture driver of the heterogenous computing platform over an I2C, I3C, SPI, or eSPI bus, a command to perform or trigger a diagnostic operation with respect to a device coupled to the EC; and receive a response from the EC. For example, the command may be transmitted during a DXE phase of a boot sequence.BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The present invention(s) is / are illustrated by way of example and is / are not limited by the accompanying figures, in which like references indicate similar elements. Elements in the figures are illustrated for simplicity and clarity, and have not necessarily been drawn to scale.
[0015] FIG. 1 is a diagram illustrating examples of components of an Information Handling System (IHS), according to some embodiments.
[0016] FIG. 2 is a diagram illustrating an example of a heterogenous computing platform configured to implement one or more aspects of an IHSs, according to some embodiments.
[0017] FIG. 3 is a diagram illustrating an example of a software and firmware architecture of an IHS, according to some embodiments.
[0018] FIG. 4 is a diagram illustrating an example of a system for handling Embedded Controller (EC) diagnostic tests using a hardware-based security architecture driver of a heterogenous computing platform, according to some embodiments.
[0019] FIG. 5 is a diagram illustrating an example of a method for handling EC diagnostic tests using a hardware-based security architecture driver of a heterogenous computing platform, according to some embodiments.DETAILED DESCRIPTION
[0020] For purposes of this disclosure, an Information Handling System (IHS) may include any instrumentality or aggregate of instrumentalities operable to compute, calculate, determine, classify, process, transmit, receive, retrieve, originate, switch, store, display, communicate, manifest, detect, record, reproduce, handle, or utilize any form of information, intelligence, or data for business, scientific, control, or other purposes. For example, an IHS may be a personal computer (e.g., desktop or laptop), tablet computer, mobile device (e.g., Personal Digital Assistant (PDA) or smart phone), server (e.g., blade server or rack server), a network storage device, or any other suitable device and may vary in size, shape, performance, functionality, and price.
[0021] An IHS may include Random Access Memory (RAM), one or more processing resources such as a Central Processing Unit (CPU) or hardware or software control logic, Read- Only Memory (ROM), and / or other types of nonvolatile memory. Additional components of an IHS may include one or more disk drives, one or more network ports for communicating with external devices as well as various Input / Output (I / O) devices, such as a keyboard, a mouse, touchscreen, and / or a video display. An IHS may also include one or more buses operable to transmit communications between the various hardware components.
[0022] The terms “heterogenous computing platform,”“heterogenous processor,” or “heterogenous platform,” as used herein, refer to an Integrated Circuit (IC) or chip (e.g., a System-On-Chip or “SoC,” a Field-Programmable Gate Array or “FPGA,” an Application-Specific Integrated Circuit or “ASIC,” etc.) containing a plurality of discrete processing circuits or semiconductor Intellectual Property (IP) cores (collectively referred to as “SoC devices” or simply “devices”) in a single electronic or semiconductor package, where each device has different processing capabilities suitable for handling a specific type of computational task. Examples of heterogenous processors include, but are not limited to: QUALCOMM's SNAPDRAGON, SAMSUNG's EXYNOS, APPLE's “A” SERIES, etc., which typically include ARM core(s).
[0023] The term “hardware-based security architecture,” as used herein, refers to security technologies that provide hardware isolation for secure code execution within a heterogenous computing platform and / or IHS. A hardware-based security architecture implements its security features and / or enclaves at the hardware level, built directly into the processor and other hardware components of the IHS, thus providing robust security capabilities that are less vulnerable to attacks. Examples of hardware-based security architectures include, but are not limited to: ARM's TRUSTZONE, APPLE′S T2 SECURITY CHIP, GOOGLE′S TITAN SECURITY CHIPS, etc. Each architecture may execute its own Operating System (OS) distinct from any host OS or service OS of the IHS.
[0024] FIG. 1 is a block diagram of examples of components of IHS 100, according to some embodiments. As shown, IHS 100 includes host processor(s) 101. In various embodiments, IHS 100 may be a single-processor system, or a multi-processor system including two or more processors. Host processor(s) 101 may include any processor capable of executing program instructions, such as an INTEL / AMD x86 processor, or any general-purpose or embedded processor implementing any of a variety of Instruction Set Architectures (ISAs), such as a Complex Instruction Set Computer (CISC) ISA, a Reduced Instruction Set Computer (RISC) ISA (e.g., one or more ARM core(s), or the like).
[0025] IHS 100 includes chipset 102 coupled to host processor(s) 101. Chipset 102 may provide host processor(s) 101 with access to several resources. In some cases, chipset 102 may utilize a QuickPath Interconnect (QPI) bus to communicate with host processor(s) 101. Chipset 102 may also be coupled to communication interface(s) 105 to enable communications between IHS 100 and various wired and / or wireless networks, such as ETHERNET, WIFI, BLUETOOTH (BT), cellular or mobile networks (e.g., Code-Division Multiple Access or “CDMA,” Time-Division Multiple Access or “TDMA,” Long-Term Evolution or “LTE,” etc.), satellite networks, or the like.
[0026] Communication interface(s) 105 may be used to communicate with peripherals devices (e.g., BT speakers, headsets, etc.). Moreover, communication interface(s) 105 may be coupled to chipset 102 via a Peripheral Component Interconnect Express (PCle) bus, or the like. Chipset 102 may be coupled to display and / or touchscreen controller(s) 104, which may include one or more Graphics Processor Units (GPUs) on a graphics bus, such as an Accelerated Graphics Port (AGP) or PCle bus. As shown, display controller(s) 104 may provide video or display signals to one or more display device(s) 111.
[0027] Display device(s) 111 may include Liquid Crystal Display (LCD), Light Emitting Diode (LED), organic LED (OLED), or other thin film display technologies. Display device(s) 111 may include a plurality of pixels arranged in a matrix, configured to display visual information, such as text, two-dimensional images, video, three-dimensional images, etc. In some cases, display device(s) 111 may operate as a single continuous display, rather than two discrete displays.
[0028] Chipset 102 may provide host processor(s) 101 and / or display controller(s) 104 with access to system memory 103. In various embodiments, system memory 103 may be implemented using any suitable memory technology, such as static RAM (SRAM), dynamic RAM (DRAM) or magnetic disks, or any nonvolatile / Flash-type memory, such as a Solid-State Drive (SSD), Non-Volatile Memory Express (NVMe), or the like.
[0029] In certain embodiments, chipset 102 may also provide host processor(s) 101 with access to one or more USB ports 108, to which one or more peripheral devices may be coupled (e.g., integrated or external webcams, microphones, speakers, etc.). Chipset 102 may further provide host processor(s) 101 with access to one or more hard disk drives, solid-state drives, optical drives, or other removable-media drives 113.
[0030] Chipset 102 may also provide access to one or more user input devices 106, for example, using a super I / O controller or the like. Examples of user input devices 106 include, but are not limited to, microphone(s) 114A, camera(s) 114B, and keyboard / mouse 114N. Other user input devices 106 may include a touchpad, stylus or active pen, totem, etc. Each of user input devices 106 may include a respective controller (e.g., a touchpad may have its own touchpad controller) that interfaces with chipset 102 through a wired or wireless connection (e.g., via communication interfaces(s) 105). In some cases, chipset 102 may also provide access to one or more user output devices (e.g., video projectors, paper printers, 3D printers, loudspeakers, audio headsets, Virtual / Augmented Reality (VR / AR) devices, etc.).
[0031] In certain embodiments, chipset 102 may further provide an interface for communications with one or more hardware sensors 110. Sensor(s) 110 may be disposed on or within the chassis of IHS 100, or otherwise coupled to IHS 100, and may include, but are not limited to: electric, magnetic, radio, optical (e.g., camera, webcam, etc.), infrared, thermal, force, pressure, acoustic (e.g., microphone), ultrasonic, proximity, position, deformation, bending, direction, movement, velocity, rotation, gyroscope, Inertial Measurement Unit (IMU), accelerometer, etc.
[0032] Basic Input / Output System (BIOS) / Unified Extensible Firmware Interface (UEFI) 107 is coupled to chipset 102. In some situations, the terms “BIOS” and “UEFI” may be used interchangeably. In operation, BIOS / UEFI 107 provides an abstraction layer that allows a host OS to interface with certain hardware components utilized by IHS 100.
[0033] When IHS 100 is powered on, host processor(s) 101 may utilize program instructions of BIOS / UEFI 107 to initialize and test hardware components coupled to IHS 100, and to load host OS 312 for use by IHS 100. As used herein, the term “pre-boot” refers to the period of time, processes, and / or environment between the initialization of host processor(s) 101 and its taking over by host OS 312, after host OS 312 is loaded and operational.
[0034] Through a hardware abstraction layer provided by BIOS / UEFI 107, software stored in system memory 103 and executed by host processor(s) 101 may interface with certain I / O devices that are coupled to IHS 100.
[0035] Embedded Controller (EC) 109 (sometimes referred to as a Baseboard Management Controller or “BMC”) includes a microcontroller unit or processing core dedicated to handling selected IHS operations not ordinarily handled by host processor(s) 101. Examples of such operations may include, but are not limited to: power sequencing, power management, receiving and processing signals from a keyboard or touchpad, as well as operating chassis buttons and / or switches (e.g., power button, laptop lid switch, etc.), receiving and processing thermal measurements (e.g., performing cooling fan control, CPU and GPU throttling, and emergency shutdown), controlling indicator Light-Emitting Diodes or “LEDs” (e.g., caps lock, scroll lock, num lock, battery, ac, power, wireless LAN, sleep, etc.), managing a battery charger and a battery, enabling remote management, diagnostic tests (or “diagnostics”), remediation over an
[0036] OOB or sideband network, etc.
[0037] Unlike other devices in IHS 100, EC 109 may be operational from the time IHS 100 is first powered on, before other devices are fully running or even powered. As such, EC 109 firmware may be responsible for interfacing with a power adapter to manage the various power states that may be supported by IHS 100. Power operations of the EC 109 may also provide other components of the IHS 100 with power status information for the IHS, such as whether IHS 100 is operating from battery power or is plugged into an AC power source. Firmware instructions utilized by EC 109 may be used to manage other core operations of IHS 100 (e.g., turbo modes, maximum operating clock frequencies of certain components, etc.).
[0038] From the perspective of users, IHS 100 may appear to be either “on” or “off,” without any other detectable power states. In some embodiments, however, an IHS 100 may support multiple power states that may correspond to the states defined in the Advanced Configuration and Power Interface (ACPI) specification, such as: S0, S1, S2, S3, S4, S5, and G3.
[0039] EC 109 may implement operations for detecting certain changes to the physical configuration or posture of IHS 100 (such as a laptop computer). For instance, when IHS 100 as a 2-in-1 laptop / tablet form factor, EC 109 may receive inputs from a lid position or hinge angle sensor 110, and may use those inputs to determine: whether the two sides of IHS 100 have been latched together to a closed position or a tablet position, the magnitude of a hinge or lid angle, etc. In response to these changes, EC 109 may enable or disable certain features of IHS 100 (e.g., front or rear facing camera, etc.).
[0040] In this manner, EC 109 may identify any number of IHS physical postures, including, but not limited to: laptop, stand, tablet, or book. For example, when an integrated display 111 of IHS 100 is open with respect to a horizontal, face-up position of an integrated keyboard, EC 109 may determine IHS 100 to be in a laptop posture. When an integrated display 111 of IHS 100 is open with respect to a horizontal keyboard portion, but the keyboard is facing down (e.g., its keys are against the top surface of a table), EC 109 may determine IHS 100 to be in a kickstand posture. When the back of an integrated display 111 is closed against the back of the keyboard portion of an IHS, EC 109 may determine IHS 100 to be folded in a tablet posture. When IHS 100 has two integrated displays 111 that are open side-by-side (e.g., in a hybrid laptop with displays in both panels), EC 109 may determine an IHS 100 to be in a book posture. When an IHS 100 is determined to be in a book posture, EC 109 may also determine if the display(s) 111 of IHS 100 are arranged in a landscape or portrait orientation, relative to the user.
[0041] In some implementations, EC 109 may be installed as part of a Trusted Execution Environment (TEE) component to the motherboard of IHS 100. As a component with hardware root-of-trust (ROT), EC 109 may be further configured to calculate hashes or signatures that uniquely identify individual components of IHS 100. In such scenarios, EC 109 may calculate a hash value based on the configuration of a hardware and / or software component coupled to IHS 100. For instance, EC 109 may calculate a hash value based on all firmware and other code or settings stored in an onboard memory of a hardware component.
[0042] Hash values may be calculated as part of a trusted process of manufacturing IHS 100 and may be maintained in secure storage as a reference signature. EC 109 may later recalculate a hash value based on instructions and settings loaded for use by a hardware component of IHS 100 and may compare the calculated value against the reference hash value to determine if any modifications have been made to the component, thus indicating that the component has been compromised. As such, EC 109 may validate the integrity of hardware and software components installed in IHS 100.
[0043] In some embodiments, EC 109 may provide an OOB (Out-Of-Band) or sideband channel that allows an Information Technology Decision Maker (ITDM) or Original Equipment Manufacturer (OEM) to manage various settings and configurations of an IHS 100. OOB is used in contradistinction with “in-band” communication channels that operate only after networking 105 other interfaces of the IHS have been initialized, and the OS of the IHS has been successfully booted.
[0044] In various embodiments, IHS 100 may be coupled to an external power source through an AC adapter, power brick, or the like. The AC adapter may be removably coupled to a battery charge controller to provide IHS 100 with a source of DC power provided by battery cells of a battery system in the form of a battery pack (e.g., a lithium ion or “Li-ion” battery pack, or a nickel metal hydride or “NiMH” battery pack including one or more rechargeable batteries). Battery Management Unit (BMU) 112 may be coupled to EC 109 and it may include, for example, an Analog Front End (AFE), storage (e.g., non-volatile memory), and a microcontroller. In some cases, BMU 112 may be configured to collect and store information, and to provide that information to EC 109.
[0045] Examples of information collectible by BMU 112 may include, but are not limited to: operating conditions (e.g., battery operating conditions including battery state information such as battery current amplitude and / or current direction, battery voltage, battery charge cycles, battery state of charge, battery state of health, battery temperature, battery usage data such as charging and discharging data; and / or IHS operating conditions such as processor operating speed data, system power management and cooling system settings, state of “system present” pin signal), environmental or context information (e.g., such as ambient temperature, relative humidity, system geolocation measured by GPS or triangulation, time and date, etc.), etc.
[0046] In various embodiments, EC 109 may be coupled (e.g., via a GPIO pin) to any of a plurality of IHS components including, but not limited to: a fan, a cable, a battery, a temperature sensor, or a display. Moreover, EC 109 may be configured to perform or trigger the performance of any number of diagnostic operations for any of these components. For example, in some cases EC 109 may be configured to request that display 111 perform a Built-In-Self-Test (BIST) and to return BIST results to EC 109 upon completion. In other cases, however, EC 109 may itself run the diagnostic operation.
[0047] In some embodiments, IHS 100 may not include all components shown in FIG. 1. In other embodiments, IHS 100 may include other components in addition to those shown in FIG. 1. Furthermore, some components illustrated as separate components in FIG. 1 may instead be integrated with other components, such that all or a portion of the operations executed by the illustrated components may instead be executed by the integrated component.
[0048] For instance, in various embodiments, host processor(s) 101 and / or other components shown in FIG. 1 (e.g., chipset 102, display controller(s) 104, communication interface(s) 105, EC 109, etc.) may be replaced by devices within a heterogenous computing platform. As such, IHS 100 may assume different form factors including, but not limited to: servers, workstations, desktops, laptops, appliances, video game consoles, tablets, smartphones, etc.
[0049] Historically, IHSs with desktop and laptop form factors have had conventional host OSs executed on INTEL or AMD's “x86”-type processors. Other types of processors, such as ARM processors, have been used in smartphones and tablet devices, which typically run thinner, simpler, and / or mobile OSs (e.g., ANDROID, IOS, WINDOWS MOBILE, etc.). More recently, however, IHS manufacturers have started producing fully-fledged desktop and laptop IHSs equipped with ARM-based, heterogenous computing platforms. Accordingly, host OSs (e.g., WINDOWS on ARM) have been developed to provide users with a familiar OS experience on those platforms.
[0050] FIG. 2 is a diagram illustrating an example of heterogenous computing platform 200 which may be implemented as part of IHS 100 and / or it may replace certain components shown in FIG.1 (e.g., host processor(s) 101)). In various embodiments, heterogenous computing platform 200 may be implemented as one or more SoCs, FPGAs, ASICs, or the like.
[0051] Heterogenous computing platform 200 may include one or more discrete and / or segregated devices or components, each having a different set of processing capabilities suitable for handling a particular type of computational task. When each device in platform 200 is tasked with executing only the types of computational tasks that it is specifically designed to execute, the overall power consumption of heterogenous computing platform 200 is reduced.
[0052] In various implementations, some of the devices in heterogenous computing platform 200 may include their own microcontroller(s) or core(s) (e.g., ARM core(s)) and corresponding firmware. In some cases, a device in platform 200 may also include its own hardware- embedded accelerator (e.g., a secondary or co-processing core coupled to a main core). Each device in heterogenous computing platform 200 may be accessible through a respective Application Programming Interface (API). Additionally, or alternatively, some devices in heterogenous computing platform 200 may execute their own OS. Additionally, or alternatively, one or more of the devices of heterogenous computing platform 200 may be virtual devices.
[0053] In the embodiment illustrated in FIG. 2, heterogenous computing platform 200 includes CPU clusters 201A-N that may correspond to system processor(s) 101, and that are intended to perform general-purpose computing operations. Each of CPU clusters 201A-N may include one or more processing cores and cache memories. In operation, CPU clusters 201A-N are available and accessible to the IHS's host OS 312 (e.g., WINDOWS on ARM) and other applications executed by IHS 100.
[0054] CPU clusters 201A-N may be coupled to memory controller 202 via internal interconnect fabric 203. Memory controller 202 may be responsible for managing system memory access for all of devices connected to internal interconnect fabric 203, which may include any communication bus suitable for inter-device communications within an SoC (e.g., Advanced Microcontroller Bus Architecture or “AMBA,” QuickPath Interconnect or “QPI,” HyperTransport or “HT,” etc.).
[0055] Devices coupled to internal interconnect fabric 203 may communicate with each other and with a host OS executed by CPU clusters 201A-N. In some cases, devices 209-211 may be coupled to internal interconnect fabric 203 via a secondary interconnect fabric (not shown). A secondary interconnect fabric may include any bus suitable for inter-device and / or inter-bus communications within an SoC.
[0056] GPU 204 produces graphical or visual content and communicates that content to a monitor or display of IHS 100 for rendering. In some embodiments, display engine or controller 209 may be designed to perform additional video enhancement operations. In operation, display engine 209 may implement procedures for providing the output of GPU 204 as a video signal to one or more external displays coupled to IHS 100 (e.g., display device(s) 111). PCle interfaces 205 provide an entry point into any additional devices external to heterogenous computing platform 200 that have a respective PCle interface (e.g., graphics cards, USB controllers, etc.).
[0057] Audio Digital Signal Processor (aDSP) 206 is a device designed to perform audio and speech operations and to perform in-line enhancements for audio input(s) and output(s). Examples of audio and speech operations include, but are not limited to: noise reduction, echo cancellation, directional audio detection, wake word detection, muting and volume controls, filters and effects, etc. In operation, input and / or output audio streams may pass through and be processed by aDSP 206, which can send the processed audio to other devices on internal interconnect fabric 203 (e.g., CPU clusters 201A-N).
[0058] In some embodiments, aDSP 206 may be configured to process one or more of heterogenous computing platform 200's sensor signals (e.g., gyroscope, accelerometer, pressure, temperature, etc.), low-power vision or camera streams (e.g., for user presence detection, onlooker detection, etc.), or battery data (e.g., to calculate a charge or discharge rate, current charge level, etc.).
[0059] Camera device 210 includes an Image Signal Processor (ISP) configured to receive and process video frames captured by a camera coupled to heterogenous computing platform 200 (e.g., in the visible and / or infrared spectrum). Video Processing Unit (VPU) 211 is a device designed to perform hardware video encoding and decoding operations, thus accelerating the operation of camera 210 and display / graphics device 209. VPU 211 may be configured to provide optimized communications with camera device 210 for performance improvements.
[0060] Sensor hub 207 may include Al capabilities designed to consolidate information received from other devices in heterogenous computing platform 200, process context and / or telemetry data streams, and provide that information to: (i) a host OS, (ii) other applications, and / or (iii) other devices in platform 200. In collecting data, sensor hub 207 may include General-Purpose Input / Output (GPIOs) that provide Inter-Integrated Circuit (I2C), Improved I2C (I3C), Serial Peripheral Interface (SPI), Enhanced SPI (eSPI), and / or serial interfaces to receive data from sensors (e.g., sensors 110, camera 210, peripherals 214, etc.). Sensor hub 207 may include a low-power core configured to execute small neural networks and specific applications, such as contextual awareness and other enhancements.
[0061] High-performance Al device 208 is a significantly more powerful processing device than sensor hub 207, and it may be designed to execute multiple complex Al algorithms and models concurrently (e.g., Natural Language Processing, speech recognition, speech-to-text transcription, video processing, gesture recognition, user engagement determinations, etc.). For example, high-performance Al device 208 may include a Neural Processing Unit (NPU), Tensor Processing Unit (TPU), Neural Network Processor (NNP), or Intelligence Processing Unit (IPU), and it may be designed specifically for Al and Machine Learning (ML), which speeds up the processing of AI / ML tasks while also freeing processor(s) 101 to perform other tasks. Using such capabilities, one or more devices of heterogenous computing platform 200 (e.g., GPU 204, aDSP 206, sensor hub 207, high-performance Al device 208, VPU 211, etc.) may be configured to execute one or more Al model(s), simulation(s), and / or inference(s).
[0062] Security device 212 may include one or more specialized security components, such as a dedicated security processor, a Trusted Platform Module (TPM), a TRUSTZONE device, a PLUTON processor, or the like. In various implementations, security device 212 may be used to perform cryptography operations (e.g., generation of key pairs, validation of digital certificates, etc.) and / or it may serve as a hardware RoT for heterogenous computing platform 200 and / or IHS 100.
[0063] Modem / wireless controller 213 may be designed to enable wired and wireless communications in any suitable frequency band (e.g., BLUETOOTH or “BT,” WiFi, CDMA, 5G, satellite, etc.), subject to Al-powered optimizations / customizations for improved speeds, reliability, and / or coverage.
[0064] Peripherals 214 may include any device coupled to heterogenous computing platform 200 (e.g., sensors 110) through mechanisms other than PCle interfaces 205. In some cases, peripherals 214 may include interfaces to integrated devices (e.g., built-in microphones, speakers, and / or cameras), wired devices (e.g., external microphones, speakers, and / or cameras, Head-Mounted Devices / Displays or “HMDs,” printers, displays, etc.), and / or wireless devices (e.g., wireless audio headsets, etc.) coupled to IHS 100.
[0065] In some implementations, EC 109 may be integrated into heterogenous computing platform 200 of IHS 100. In other implementations EC 109 may be external to the heterogenous computing platform 200 (i.e., the EC 109 residing in its own semiconductor package) but coupled to integrated bridge 216 via an interface (e.g., enhanced SPI or “eSPI”), thus supporting the EC's ability to access the SoC's interconnect fabric 203, including sensor hub 207 and sensor(s) 110. Through this connectivity supported by interconnect fabric 203, EC 109 may directly access and / or operate most or all of devices 201-216, 110 of heterogenous computing platform 200.
[0066] FIG. 3 is a diagram illustrating an example of architecture 300 usable with IHS 100. Particularly, architecture 300 includes IHS 100 (e.g., implementing aspects of IHS 100 and / or platform 200) coupled to storage device 302 (e.g., NVMe, SSD, etc.), secondary or companion IHS 303 (e.g., a smart phone, a laptop, etc.), and cloud or remote services 304. Cloud 304 may include backend or remote services 305, policy services 306, and web applications 307. In some cases, components of cloud 304 may be accessible to IHS 100 and / or secondary IHS 303, and configurable via ITDM management console 308.
[0067] IHS 100 may include hardware / EC / firmware layer 309, BIOS / UEFI layer 310, and OS layer 311. Specifically, OS layer 311 includes host OS 312 executed by host processor(s) 101. A variety of software applications may operate within OS 312, where these applications may include user applications 313 and system applications 314. Applications that operate within the OS 312 may also include one or more telemetry applications 350.
[0068] OS layer 311 may also include various drivers and other core OS operations, such as the operation of a kernel. As described, various components of heterogenous computing platform 200 may independently run their own OS, such as a Real-Time OS (RTOS) run by an SoC.
[0069] Within IHS 100, RTOSs executed by individual components of the heterogenous computing platform 200 are deemed distinct from service OS 316, which includes its own applications 317 and services 318. Hardware device drivers 315 used by host OS 312 and / or by service OSs 316 may support the operation of IHS 100 hardware.
[0070] BIOS / UEFI layer 310 may include pre-OS core services 319, pre-OS applications 320, and pre-OS network stack 321 that are each executed by BIOS / UEFI 107. BIOS core services 319 may include operations for identifying and validating the detected hardware components of IHS 100. BIOS applications 320 may include operations for interfacing with certain hardware devices of IHS 100, in particular user input devices. The network stack 321 of BIOS 310 may be utilized during initialization of IHS 100 in support of validation procedures, such as in retrieving reference signatures corresponding to authentic firmware instructions for hardware components of IHS 100.
[0071] As illustrated, IHS 100 also includes a hardware / EC / firmware layer 309 with EC 109 and sensor hub 207. As described above, EC 109 may implement a variety of procedures for management of individual hardware of IHS 100. EC 109 is configured to execute one or more sensor services 323 that interface with sensor hub 207 in implementing various operations, such response to user-presence determination by the sensor hub 207 that is acted upon by the EC 109 in initiation heightened security protocols. Moreover, EC 109 may interface with some or all individual hardware components / systems of IHS 100 via sideband management channels that are separate from inline communication channels used by host processor(s) 101 and SoCs.
[0072] As described above, sensor hub 207 may receive inputs from some or all sensors 110A-N of an IHS 100. Sensor hub 207 may implement a variety of sensor service(s) 322 for communicating with and collecting data from sensors 110A-N. In some embodiments, sensor hub 207 may implement shock detection procedures that may incorporate inputs from inertial and other sensors 110A-N of IHS 100. Shock detection procedures may detect shocks experienced by IHS 100 and may characterize and assess possible damage to IHS 100.
[0073] When diagnostic tests are running, several operations may be offloaded from host processor(s) 101 to EC 109. In those cases, however, BIOS / UEFI 107 ordinarily must wait until EC 109 completes the diagnostics before initiating subsequent operations. For example, if the a diagnostic test requires changing colors of an LCD display, this operation must be completed before BIOS / UEFI 107 can move on.
[0074] This results in host processor(s) idling times, long boot sequences, more tedious troubleshooting, etc. In x86 platforms, for example, prior to sending a diagnostic request or command to EC 109, host processor(s) 101 is locked in System Management Mode (SMM) upon the setting of a System Management Interrupt (SMI) by BIOS / UEFI 107.
[0075] To address these, and other concerns, systems and methods for handling EC diagnostics using a hardware-based security architecture driver of a heterogenous computing platform are described.
[0076] FIG. 4 is a diagram illustrating an example of system 400 for handling EC diagnostics using a hardware-based security architecture driver of heterogenous computing platform 200. Particularly, system 400 includes BIOS / UEFI 107, host OS 312, service OS 316, normalization engine 401, hardware-based security architecture driver 402, bus 403, EC 109, fan 404A, cable 404B, battery 404C, thermal sensors 404D, and display 404N coupled and / or in communication as shown.
[0077] BIOS / UEFI 107, host OS 312, and / or service OS 316 may include one or more agents, drivers, or applications configured to request EC-based diagnostic operations by communicating with hardware-based security architecture driver 402 through normalization engine 401. Such requests may be originated as part of IHS 100′s boot sequence or initialization process, and / or at any other time at the command of a user or ITDM (e.g., via a BIOS / UEFI menu, an OS Graphical User Interface or “GUI,” etc.). In some cases, the request may be issued by BIOS / UEFI 107 during a Driver Execution Environment (DXE) phase of a boot sequence.
[0078] An original diagnostic request issued by BIOS / UEFI 107, host OS 312, and / or service OS 316 may be processed by normalization engine 401, which may be implemented as an application executable by EC 109, BIOS / UEFI 107, and / or host OS 312.
[0079] Normalization engine 401 may include a diagnostics abstraction protocol that matches the request to a corresponding entry in a Look-Up Table (LUT) of definitions to translate the request into EC-specific commands (e.g., as provided by the EC's OEM) suitable for fulfilling the original diagnostic request. For example, the original diagnostic request may be for a “battery test,” and the output of normalization engine 401 may identify which EC-specific commands should be issued to fulfill such a request. EC-specific commands are then transmitted to EC 109 through hardware-based security architecture driver402's API, which places the commands in appropriate hardware-based security architecture registers.
[0080] In various embodiments, by using hardware-based security architecture driver 402, system 400 enables communications between a hardware-based security architecture, such as TRUSTZONE (e.g., an isolated, secure, or segregated portion of host processor(s) 101), and EC 109 over bus 403. Bus 403 may include an I2C, I3C, SPI, or eSPI bus. Also, such communications through hardware-based security architecture driver 402 (as well as the diagnostic operations themselves) do not invoke any System Management Interrupts (SMIs) and / or otherwise cause IHS 100 to enter System Management Mode (SMM).
[0081] Hardware-based security architecture driver 402 may communicate a command to EC 109 to trigger a diagnostic operation, and in response EC 109 may trigger, run, execute, or delegate the diagnostic operation to devices 404A-N (e.g., cooling fan, cable, battery, temperature, displays, docking stations, etc.) while host processor(s) 101 remains in operation. As such, system 400 enables multitasking, multithreading, load balancing, and / or prioritization of multiple diagnostics operations by EC 109 and / or host processor(s) 101 concurrently and / or simultaneously.
[0082] When EC 109 receives more than one diagnostic command in a single request, or if it receives a subsequent request before it has processed a current or prior request, diagnostic commands may be placed in a queue. In some cases, just received diagnostics commands or operations, as well as commands and operations placed in the queue, may be handled based at least in part upon a diagnostics policy.
[0083] In some cases, the diagnostics policy may be provided by an OEM of IHS 100 and / or EC 109. The policy may include one or more rules, for example, in an Extensible Markup Language (XML) or a JavaScript Object Notation (JSON) file usable by EC 109 to determine an order in which to perform or trigger diagnostic operations based, at least in part, upon context information. The context information may include, for example, a location of the IHS, an identity of a user of the IHS, a host OS of the IHS, a network connectivity of the IHS, etc.
[0084] In some cases, a diagnostics policy rule may prevent EC 109 from triggering a diagnostic operation based, at least in part, upon context information. In other cases, a policy rule may require that EC 109 trigger another diagnostic operation (different that the operations / tests requested) based, at least in part, upon context information.
[0085] FIG. 5 is a diagram illustrating an example of method 500 for handling EC diagnostics using hardware-based security architecture driver 401 of heterogenous computing platform 200. In various embodiments, method 500 may be performed, at least in part, by EC 109.
[0086] Particularly, method 500 starts at 501. At 502, EC 109 receives, from hardware- based security architecture driver 401, message(s), request(s), or command(s) to trigger one or more diagnostic operation(s). These message(s), request(s), or command(s) may identify one or more generic diagnostics to be performed by EC 109 and / or parameters thereof. In some cases, message(s), request(s), or command(s) may be issued by a BIOS of heterogenous computing platform 200 during a Driver Execution Environment (DXE) phase of a boot sequence of IHS 100.
[0087] Additionally, or alternatively, these message(s), request(s), or command(s) may include EC-specific commands (e.g., by an OEM driver or agent), specifically for EC 109 hardware / firmware, translated to fulfill the generic diagnostic. For instance, these message(s), request(s), or command(s) originated by BIOS / UEFI 107, OS 312, and / or service OS 316 may be transmitted to EC 109 over bus 402. In some cases, when two or more diagnostic instructions or operations are included in the message(s), request(s), or command(s), and EC 109 may place them in a queue.
[0088] At 503, EC 109 determines whether to apply a policy to a just received diagnostic message, request, or command, or to a queue of them. If not, at 504 EC 109 executes or triggers the execution of (e.g., by a device to be diagnosed) the just received or queued diagnostic operation. Examples of diagnostic operations include, but are not limited to, a device's BIST, an EC-managed hardware and / or firmware functional test, etc.). In some cases, EC 109 may return a response to back to BIOS / UEFI 107, OS 312, and / or service OS 316 through hardware-based security architecture driver 402. The response may include, for example, an indication of device status and / or a result of a diagnostic operation (e.g., pass / fail, a score, an error, a timeout, etc.).
[0089] At 506, if a diagnostics policy is to be applied, EC 109 evaluates the command(s) against one or more policy rules, for example, based on context information. Depending upon the result of the evaluation, EC 109 may trigger one or more diagnostic operations at 504 and report them back.
[0090] For example, depending upon a location of IHS 100, an identity of a user, a host OS, or a network connectivity of the IHS, EC 109 may skip a diagnostic operation, replace a diagnostic operation with another, and / or add diagnostic operations to the original request; in which case the response may also include results of these modified diagnostic operations. Method 500 ends at 505.
[0091] To implement various operations described herein, computer program code (i.e., program instructions for carrying out these operations) may be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, Python, C++, or the like, conventional procedural programming languages, such as the “C” programming language or similar programming languages, or any of machine learning software. These program instructions may also be stored in a computer readable storage medium that can direct a computer system, other programmable data processing apparatus, controller, or other device to operate in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the operations specified in the block diagram block or blocks.
[0092] Program instructions may also be loaded onto a computer, other programmable data processing apparatus, controller, or other device to cause a series of operations to be performed on the computer, or other programmable apparatus or devices, to produce a computer implemented process such that the instructions upon execution provide processes for implementing the operations specified in the block diagram block or blocks.
[0093] Modules implemented in software for execution by various types of processors may, for instance, include one or more physical or logical blocks of computer instructions, which may, for instance, be organized as an object or procedure. Nevertheless, the executables of an identified module need not be physically located together but may include disparate instructions stored in different locations which, when joined logically together, include the module and achieve the stated purpose for the module. Indeed, a module of executable code may be a single instruction, or many instructions, and may even be distributed over several different code segments, among different programs, and across several memory devices.
[0094] Similarly, operational data may be identified and illustrated herein within modules and may be embodied in any suitable form and organized within any suitable type of data structure. Operational data may be collected as a single data set or may be distributed over different locations including over different storage devices.
[0095] Reference is made herein to “configuring” a device or a device “configured to” perform some operation(s). It should be understood that this may include selecting predefined logic blocks and logically associating them. It may also include programming computer software-based logic of a retrofit control device, wiring discrete hardware components, or a combination thereof. Such configured devices are physically designed to perform the specified operation(s).
[0096] It should be understood that various operations described herein may be implemented in software executed by processing circuitry, hardware, or a combination thereof. The order in which each operation of a given method is performed may be changed, and various operations may be added, reordered, combined, omitted, modified, etc. It is intended that the invention(s) described herein embrace all such modifications and changes and, accordingly, the above description should be regarded in an illustrative rather than a restrictive sense.
[0097] Unless stated otherwise, terms such as “first” and “second” are used to arbitrarily distinguish between the elements such terms describe. Thus, these terms are not necessarily intended to indicate temporal or other prioritization of such elements. The terms “coupled” or “operably coupled” are defined as connected, although not necessarily directly, and not necessarily mechanically. The terms “a” and “an” are defined as one or more unless stated otherwise. The terms “comprise” (and any form of comprise, such as “comprises” and “comprising”), “have” (and any form of have, such as “has” and “having”), “include” (and any form of include, such as “includes” and “including”) and “contain” (and any form of contain, such as “contains” and “containing”) are open-ended linking verbs.
[0098] As a result, a system, device, or apparatus that “comprises,”“has,”“includes” or “contains” one or more elements possesses those one or more elements but is not limited to possessing only those one or more elements. Similarly, a method or process that “comprises,”“has,”“includes” or “contains” one or more operations possesses those one or more operations but is not limited to possessing only those one or more operations.
[0099] Although the invention(s) is / are described herein with reference to specific embodiments, various modifications and changes can be made without departing from the scope of the present invention(s), as set forth in the claims below. Accordingly, the specification and figures are to be regarded in an illustrative rather than a restrictive sense, and all such modifications are intended to be included within the scope of the present invention(s). Any benefits, advantages, or solutions to problems that are described herein with regard to specific embodiments are not intended to be construed as a critical, required, or essential feature or element of any or all the claims.
Claims
1. An Information Handling System (IHS), comprising:a heterogenous computing platform; andan Embedded Controller (EC) integrated into or coupled to the heterogenous computing platform, the EC configured to:receive, from a hardware-based security architecture driver of the heterogenous computing platform, a command to perform or trigger a diagnostic operation; andrespond to the command.
2. The IHS of claim 1, wherein the heterogenous computing platform comprises: a System-On-Chip (SoC), a Field-Programmable Gate Array (FPGA), or an Application-Specific Integrated Circuit (ASIC).
3. The IHS of claim 1, wherein the heterogenous computing platform comprises a Reduced Instruction Set Computer (RISC) processor coupled to an interconnect.
4. The IHS of claim 3, wherein the interconnect comprises at least one of: an Advanced Microcontroller Bus Architecture (AMBA) bus, a QuickPath Interconnect (QPI) bus, or a HyperTransport (HT) bus.
5. The IHS of claim 1, wherein the request is received by the EC from the heterogenous computing platform over an Inter-Integrated Circuit (I2C), Improved I2C (I3C), Serial Peripheral Interface (SPI), or Enhanced SPI (eSPI) bus.
6. The IHS of claim 1, wherein the hardware-based security architecture comprises a TRUSTZONE architecture.
7. The IHS of claim 1, wherein the command is issued by a Basic Input / Output System (BIOS) of the heterogenous computing platform during a Driver Execution Environment (DXE) phase of a boot sequence.
8. The IHS of claim 7, wherein the EC is configured to perform or trigger the diagnostic operation in the absence of any System Management Interrupt (SMI) by the heterogenous computing platform.
9. The IHS of claim 7, wherein the EC is configured to perform or trigger the diagnostic operation concurrently with one or more diagnostic operations performed by the heterogenous computing platform.
10. The IHS of claim 1, wherein to perform or trigger the diagnostic operation, the EC is configured to communicate with at least one of: a fan, a cable, a battery, a temperature sensor, or a display identified based, at least in part, upon the request.
11. The IHS of claim 1, wherein the EC is configured to:receive, from the hardware-based security architecture driver, another command to perform or trigger another diagnostic operation;queue the other diagnostic operation; andrespond to the other command.
12. The IHS of claim 11, wherein the command and the other command are received in a same request issued by a Basic Input / Output System (BIOS) of the heterogenous computing platform to the hardware-based security architecture driver.
13. The IHS of claim 12, wherein the EC is configured to perform or trigger one or more diagnostic operations in the queue based, at least in part, upon a policy.
14. The IHS of claim 13, wherein the policy comprises one or more rules usable by the EC to determine an order in which to perform or trigger the one or more diagnostic operations based, at least in part, upon context information.
15. The IHS of claim 14, wherein the context information comprises at least one of: a location of the IHS, an identity of a user of the IHS, a host Operating System (OS) of the IHS, or a network connectivity of the IHS.
16. In an Information Handling System (IHS) comprising a heterogenous computing platform having a host processor and an Embedded Controller (EC) coupled to the host processor, a method comprising:receiving, by the EC from a hardware-based security architecture driver of the heterogenous computing platform, a command to trigger a diagnostic operation, wherein the command is issued by a Basic Input / Output System (BIOS); andhandling the command.
17. The method of claim 16, further comprising not triggering the diagnostic operation based, at least in part, upon a policy.
18. The method of claim 16, further comprising triggering another diagnostic operation based, at least in part, upon a policy.
19. An heterogenous computing platform, comprising:a host processor configured to execute a Basic Input / Output System (BIOS); andan Embedded Controller (EC) coupled to the host processor, wherein the BIOS is configured to:transmit to the EC, through a hardware-based security architecture driver of the heterogenous computing platform over an Inter-Integrated Circuit (I2C), Improved I2C (I3C), Serial Peripheral Interface (SPI), or Enhanced SPI (eSPI) bus, a command to perform or trigger a diagnostic operation with respect to a device coupled to the EC; andreceive a response from the EC.
20. The heterogenous computing platform of claim 19, wherein the command is transmitted during a Driver Execution Environment (DXE) phase of a boot sequence.
Citation Information
Patent Citations
Cooperative embedded agents
US20050216577A1
Systems And Methods To Securely Inject Binary Images And Code Into Firmware
US20170010884A1
Multiple Hardware-Separated Computer Operating Systems within a Single Processor Computer System to Prevent Cross-Contamination between Systems
US20180032733A1
Multi-form factor information handling system (IHS) with layered, foldable, bendable, flippable, rotatable, removable, displaceable, and / or slideable component(s)
US20200042045A1
Method and Apparatus for Providing a Root of Trust using a Baseboard Management Controller
US20200042710A1
Cited By
Roots of trust in intellectual property (IP) blocks in a system on a chip (SOC)
US20240195635A1